01Roles & Access

OpenFGA policy registry

Access is enforced by OpenFGA — Zanzibar-style fine-grained authorization.
Every API call resolves a check before any database access. Audit log captures every grant and revocation.
RoleScopePermissionsPeople
SuperAdminGlobal
all:*
1
Admin / OpsTenant
enrollment:*verification:*moderation:*audit:read
6
LegalTenant
contracts:*disputes:*
2
FinanceTenant
invoices:*payouts:*ledger:readtax:*
2
ManagerRoster
talent:assigneddeals:*campaigns:*
6
AgentRoster
talent:assigneddeals:*
8
Client UserCompany
bookings:ownfinance:own
423
TalentSelf
profile:selfbookings:ownearnings:own
1,847
CustomerPublic
browse:publicnewsletter:opt-in
18,420